Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Finance
    3. >GET IN SHAPE FOR GDPR
    Finance

    Get in Shape for Gdpr

    Published by Gbaf News

    Posted on April 20, 2017

    10 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    Image depicting the Swedish central bank's decision to cut interest rates to 2.50% as the economy stabilizes, highlighting cautious monetary policy for 2025.
    Swedish central bank cutting interest rates - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Dr Jamie Graves, CEO at cyber security specialists ZoneFox

    Dr Jamie Graves

    Dr Jamie Graves

    From MiFID through to the Basel Accords and multiple other Capital Requirements, the finance sector has grown used to unpicking complex EU regulation. However, the European General Data Protection Regulation (GDPR) is a different type of beast because it impacts every nook and cranny of your business. Even ones you weren’t aware existed.

    Why? Simple: data has taken root in your organisation. You need it in order to retain customers, deliver innovative new products to the market and execute a fantastic customer service experience. Especially as customers now bank across multiple applications and devices. The hard truth is that without data you simply can’t function, certainly not meaningfully. But how that data is managed and protected currently varies wildly, something the GDPR looks to rectify by standardising how data is protected and accessed across the EU.

    It’s a highly ambitious piece of regulation and the triggering of Article 50 shouldn’t lure companies into complacency – if you want to do business in the global economy and deliver data across borders, you will need to comply. The regulation brings with it big changes and so, if you haven’t already, it’s important to get your ducks in a row. The question is, how can you prepare?

    For me, the regulation broadly falls into three distinct action areas that offer the opportunity to enhance information security from a technical, governance and legal perspective: proactivity, ensuring GDPR is a board level priority and risk mitigation.

    Proactivity

    When it comes to security, being on the front foot is absolutely key.  Most companies don’t know how and where all its data is processed or stored across the organisation, or whether it is accessed always  in line with company policy. Auditing this process is the ideal  place to start – after all, as the saying goes, knowledge is power. From this audit you will be able to get a much better understanding of:

    • What measures you have in place to protect data, especially personally identifiable information. Ensure you perform vulnerability assessments and penetration tests to determine if unauthorised access and downloading are possible. This is a great exercise and also offers the opportunity to test your data encryption standards
    • The relationship your organisation has with third-parties. Who do you share data with? And how do third-parties collect data from your business? Longer term, you will need to ensure that your data supply chain is GDPR compliant – the onus is very much on you to take responsibility for this
    • Have your legal and compliance teams go over end-user agreements to ensure that all data subjects have willingly agreed
    • Ensure that how you tell people you use their data is actually how you use it. An outside opinion can help here, so don’t be afraid to engage an expert to advise
    • Does your current data storage solution have any risks associated with it? If so, create a risk registry so that you can tackle these

     Ensuring GDPR is a priority

    Being proactive will help you to understand the unique risks and vulnerabilities your organisation faces – in relation to complying with GDPR. This understanding forms the basis of a robust strategy to be presented to company directors. The exec board hears about so many internal projects, all of which are competing for internal resources and funding, so it’s important to present the right information in order to secure the resources you need:

    • Any discrepancies between end-user agreements and GDPR requirements as well as a clear roadmap for how to reconcile the two
    • Create risk-based metrics based on vulnerability assessments and penetration tests to outline any weaknesses in your data defences. Don’t forget, the board will be looking to you to bring solutions as well as problems to the table
    • Be clear about any deviations from GDPR and present a strategy encompassing technical, legal and compliance requirements with a timeline for ensuring compliance by May 2018 alongside associated risks of the data registry

    Risk mitigation

    The road to successful GDPR compliance will require the strong mitigation of risks. This is an important step because arguably data is the most valuable artefact on the internet and as a result the most traceable. We’ve all seen the headlines resulting from data breaches; companies that are victim to attack suffer brand damage, lose customers and as a result see a real impact on their bottom line. With GDPR the onus on companies to take responsibility increases dramatically. Therefore, it is imperative that you:

    • Classify your data as this is vital to preventing data loss
    • Continuously monitor the environment to ensure your data stays exactly where it is supposed to and doesn’t walk unauthorised out of the front door
    • Encrypt your databases. This might seem like an obvious point, but not all companies are following this basic rule. Apply strong algorithms so that even if the bad guys steal your data you render it useless to them

    GDPR might feel all consuming, but broken down into these three key areas it becomes much more manageable. It is also a significant opportunity to redefine your relationship with your increasingly data-savvy customers and create a new era in which data is shown the respect and protection it deserves.

    The opportunity is there to become a real industry leader in data security– those that seize it will prosper those that don’t risk being consigned to history.

    Dr Jamie Graves, CEO at cyber security specialists ZoneFox

    Dr Jamie Graves

    Dr Jamie Graves

    From MiFID through to the Basel Accords and multiple other Capital Requirements, the finance sector has grown used to unpicking complex EU regulation. However, the European General Data Protection Regulation (GDPR) is a different type of beast because it impacts every nook and cranny of your business. Even ones you weren’t aware existed.

    Why? Simple: data has taken root in your organisation. You need it in order to retain customers, deliver innovative new products to the market and execute a fantastic customer service experience. Especially as customers now bank across multiple applications and devices. The hard truth is that without data you simply can’t function, certainly not meaningfully. But how that data is managed and protected currently varies wildly, something the GDPR looks to rectify by standardising how data is protected and accessed across the EU.

    It’s a highly ambitious piece of regulation and the triggering of Article 50 shouldn’t lure companies into complacency – if you want to do business in the global economy and deliver data across borders, you will need to comply. The regulation brings with it big changes and so, if you haven’t already, it’s important to get your ducks in a row. The question is, how can you prepare?

    For me, the regulation broadly falls into three distinct action areas that offer the opportunity to enhance information security from a technical, governance and legal perspective: proactivity, ensuring GDPR is a board level priority and risk mitigation.

    Proactivity

    When it comes to security, being on the front foot is absolutely key.  Most companies don’t know how and where all its data is processed or stored across the organisation, or whether it is accessed always  in line with company policy. Auditing this process is the ideal  place to start – after all, as the saying goes, knowledge is power. From this audit you will be able to get a much better understanding of:

    • What measures you have in place to protect data, especially personally identifiable information. Ensure you perform vulnerability assessments and penetration tests to determine if unauthorised access and downloading are possible. This is a great exercise and also offers the opportunity to test your data encryption standards
    • The relationship your organisation has with third-parties. Who do you share data with? And how do third-parties collect data from your business? Longer term, you will need to ensure that your data supply chain is GDPR compliant – the onus is very much on you to take responsibility for this
    • Have your legal and compliance teams go over end-user agreements to ensure that all data subjects have willingly agreed
    • Ensure that how you tell people you use their data is actually how you use it. An outside opinion can help here, so don’t be afraid to engage an expert to advise
    • Does your current data storage solution have any risks associated with it? If so, create a risk registry so that you can tackle these

     Ensuring GDPR is a priority

    Being proactive will help you to understand the unique risks and vulnerabilities your organisation faces – in relation to complying with GDPR. This understanding forms the basis of a robust strategy to be presented to company directors. The exec board hears about so many internal projects, all of which are competing for internal resources and funding, so it’s important to present the right information in order to secure the resources you need:

    • Any discrepancies between end-user agreements and GDPR requirements as well as a clear roadmap for how to reconcile the two
    • Create risk-based metrics based on vulnerability assessments and penetration tests to outline any weaknesses in your data defences. Don’t forget, the board will be looking to you to bring solutions as well as problems to the table
    • Be clear about any deviations from GDPR and present a strategy encompassing technical, legal and compliance requirements with a timeline for ensuring compliance by May 2018 alongside associated risks of the data registry

    Risk mitigation

    The road to successful GDPR compliance will require the strong mitigation of risks. This is an important step because arguably data is the most valuable artefact on the internet and as a result the most traceable. We’ve all seen the headlines resulting from data breaches; companies that are victim to attack suffer brand damage, lose customers and as a result see a real impact on their bottom line. With GDPR the onus on companies to take responsibility increases dramatically. Therefore, it is imperative that you:

    • Classify your data as this is vital to preventing data loss
    • Continuously monitor the environment to ensure your data stays exactly where it is supposed to and doesn’t walk unauthorised out of the front door
    • Encrypt your databases. This might seem like an obvious point, but not all companies are following this basic rule. Apply strong algorithms so that even if the bad guys steal your data you render it useless to them

    GDPR might feel all consuming, but broken down into these three key areas it becomes much more manageable. It is also a significant opportunity to redefine your relationship with your increasingly data-savvy customers and create a new era in which data is shown the respect and protection it deserves.

    The opportunity is there to become a real industry leader in data security– those that seize it will prosper those that don’t risk being consigned to history.

    More from Finance

    Explore more articles in the Finance category

    Image for Blaze at Russia's Baltic Sea port of Ust-Luga after major Ukrainian drone attack
    Blaze at Russia's Baltic Sea Port of Ust-Luga After Major Ukrainian Drone Attack
    Image for Morning Bid: Deal, or no deal?
    Morning Bid: Deal, or No Deal?
    Image for Labubu maker Pop Mart meets 2025 revenue expectations
    Labubu Maker Pop Mart Meets 2025 Revenue Expectations
    Image for Israel strikes Tehran as Trump says US negotiating to end war
    Israel Strikes Tehran as Trump Says US Negotiating to End War
    Image for South Korea, Germany exposed to rare earths shortage, Australia's Arafura says
    South Korea, Germany Exposed to Rare Earths Shortage, Australia's Arafura Says
    Image for Currency markets drift as traders sceptical of US efforts to end Iran war
    Currency Markets Drift as Traders Sceptical of US Efforts to End Iran War
    Image for Stocks bounce and oil retreats on Mideast ceasefire reports
    Stocks Bounce and Oil Retreats on Mideast Ceasefire Reports
    Image for Equinor CEO says EU unlikely to increase Russian gas imports
    Equinor CEO Says EU Unlikely to Increase Russian Gas Imports
    Image for Openreach taps Google AI to speed fibre rollout, cut emissions
    Openreach Taps Google AI to Speed Fibre Rollout, Cut Emissions
    Image for UK consumer sentiment falls as Iran war rages, KPMG says
    UK Consumer Sentiment Falls as Iran War Rages, Kpmg Says
    Image for US oil prices fall on prospect of Middle East ceasefire easing supply disruption
    US Oil Prices Fall on Prospect of Middle East Ceasefire Easing Supply Disruption
    Image for Lamborghinis stranded in Sri Lanka as war disrupts Asia's used-car trade 
    Lamborghinis Stranded in Sri Lanka as War Disrupts Asia's Used-Car Trade 
    View All Finance Posts
    Previous Finance PostSurvey: Despite Privacy Concerns, Consumers Will Share Personal Data if IT Saves Money or Resolves Customer Service Issues
    Next Finance PostDespite Concerns Over Brexit, UK Rated as Most Attractive Commercial Real Estate Market